CVE-2025-46199
- EPSS 0.8%
- Veröffentlicht 25.07.2025 18:15:26
- Zuletzt bearbeitet 15.08.2025 14:32:27
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields
CVE-2025-46198
- EPSS 0.63%
- Veröffentlicht 25.07.2025 00:00:00
- Zuletzt bearbeitet 20.08.2025 20:05:24
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element
CVE-2024-35498
- EPSS 0.38%
- Veröffentlicht 06.01.2025 19:15:12
- Zuletzt bearbeitet 17.04.2025 02:36:22
A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-34082
- EPSS 3.05%
- Veröffentlicht 15.05.2024 17:15:12
- Zuletzt bearbeitet 02.01.2025 23:06:29
Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hash...
CVE-2024-28118
- EPSS 1.22%
- Veröffentlicht 21.03.2024 22:15:12
- Zuletzt bearbeitet 02.01.2025 22:59:47
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a previous SSTI...
CVE-2024-28119
- EPSS 1.58%
- Veröffentlicht 21.03.2024 22:15:12
- Zuletzt bearbeitet 02.01.2025 23:00:20
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an attacker can redefine the escape function and execute arbitrary commands. Twig processi...
CVE-2024-27921
- EPSS 60.59%
- Veröffentlicht 21.03.2024 22:15:11
- Zuletzt bearbeitet 02.01.2025 22:57:17
Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .c...
CVE-2024-28116
- EPSS 5.76%
- Veröffentlicht 21.03.2024 22:15:11
- Zuletzt bearbeitet 02.01.2025 22:57:51
Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code ...
CVE-2024-28117
- EPSS 1.38%
- Veröffentlicht 21.03.2024 22:15:11
- Zuletzt bearbeitet 02.01.2025 22:58:56
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions on twig functions like twig_array_map, allowin...
CVE-2024-27923
- EPSS 1.36%
- Veröffentlicht 21.03.2024 02:52:21
- Zuletzt bearbeitet 02.01.2025 23:02:44
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient permission validation and inadequate file name validation. This may lead to remote code execution. Ve...